---
url: 'https://dxpr.com/us-sovereignty'
title: 'US Sovereignty'
author:
  name: Jurriaan
  url: 'https://dxpr.com/users/jurriaan'
date: '2026-10-06T07:58:06+00:00'
copyright: 'Copyright DXPR. All rights reserved.'
type: drag_and_drop_page
summary: 'Your content stays stateside.DXPR Builder lives inside your own Drupal site. Your content stays in your database. Our US servers run in Washington, DC, with AI pipelines on US-geolocked infrastructure.'
image: 'https://dxpr.com/sites/default/files/us-sovereignty.webp'
published: true
---
##  [US Sovereignty](/us-sovereignty)

# Your content stays stateside.

DXPR Builder lives inside your own Drupal site. Your content stays in your database. Our US servers run in Washington, DC, with AI pipelines on US-geolocked infrastructure.

[Talk to Sales](/contact)

[View security policy](/security-advisories/policy)

## Your content lives in your database.

Most page builders extract your content into their own cloud. DXPR Builder is a Drupal module: it runs inside your site, stores everything in your Drupal database, and renders pages from your own server. Personalization, A/B testing, and reinforcement learning all execute against your local data store. There is no DXPR content lake, no third-party CDN copy, no shadow replica.

Select a layer to see the product control behind it: where content rests, which third parties are in the path, and how AI processing stays under US jurisdiction.

#### Content storage

Site content lives in structured Drupal content types with manageable fields. Your content stays in your database; personalization, A/B test variants and learning data never leave your Drupal site.

#### Third-party calls

Every AI capability is routed through a provider you choose and can audit. On this site all chat capabilities route through DXPR, with no silent third party in the path.

#### AI processing

Administrators pick the default model and restrict which models end users may select, backed by frontier US model providers alongside the EU privacy option. Run text, image and rewriting workloads on US-hosted endpoints under US jurisdiction.

- [Content storage](#us-data-storage)Site content lives in structured Drupal content types with manageable fields. Your content stays in your database; personalization, A/B test variants and learning data never leave your Drupal site.
- [Third-party calls](#us-data-third-party)Every AI capability is routed through a provider you choose and can audit. On this site all chat capabilities route through DXPR, with no silent third party in the path.
- [AI processing](#us-data-ai-processing)Administrators pick the default model and restrict which models end users may select, backed by frontier US model providers alongside the EU privacy option. Run text, image and rewriting workloads on US-hosted endpoints under US jurisdiction.

## Move at the pace of American business.

A product launch in New York. A recruiting campaign in Texas. Your teams need to publish while the web team keeps a consistent platform behind them.

Give marketers reusable layouts and visual editing inside Drupal. Your web team continues managing the roles, revisions and publishing process your organization already uses.

[Explore DXPR for Enterprise →](/enterprise)

## Washington, DC servers. US-geolocked services.

### Servers in Washington, DC

DXPR’s US servers are hosted in Washington, DC. Hosting, CDN endpoints, backups, and monitoring stay within the United States.

### US-geolocked AI pipelines

AI text generation, image generation, and content rewriting run on US-hosted model endpoints. Prompts and outputs stay within US jurisdiction.

### Your database, your control

DXPR Builder stores all content, layouts, A/B test variants, and RL personalization data in your Drupal database. We never see it, copy it, or cache it.

## Where your data lives in the United States.

DXPR’s US servers are hosted in Washington, DC. Your Drupal site stays with your chosen hosting provider. Review the location of each service with your security and procurement teams.

Content

Your Drupal databaseWherever you host your Drupal site; DXPR never extracts it

A/B testing

Your Drupal databaseTest variants, audience segments, and results stored locally

RL personalisation

Your Drupal databaseReinforcement learning models train on local behavioural data

AI generation

US-geolocked endpointsText and image generation hosted in US data centres

DXPR servers

Washington, DC, United StatesDXPR-operated US infrastructure

License server

Washington, DC, United StatesHosted on DXPR’s US infrastructure

Support

US business hoursDedicated US-timezone support channel

## Support for your compliance review.

- **Named US server location**Washington, DC, for DXPR’s US servers; US-geolocked AI, backups, and monitoring
- **US-geolocked AI**Text and image generation run on US-hosted model endpoints exclusively
- **ADA and Section 508 accessibility**In DXPR Builder output and the DXPR Builder interface itself
- **WCAG 2.2 AA conformance**With documented accessibility statement and ongoing VPAT coverage
- **Drupal security team coverage**DXPR Builder and DXPR Theme are covered projects on drupal.org
- **Responsible disclosure policy**With documented SLAs for vulnerability response
- **No content extraction**All page content, A/B variants, personalization data, and analytics stay in your Drupal database
- **Open-source foundation**DXPR Builder is a Drupal module you can audit, extend, and fork
- **CCPA compliance**No sale or sharing of personal information from DXPR-operated services
- **Encryption in transit**TLS 1.2+ and at rest for all DXPR-operated services
- **HIPAA-compatible architecture**Because content stays in your Drupal database, DXPR Builder does not process or store protected health information; your BAA is with your hosting provider, not with us
- **Executive Order 14028 alignment**Open-source supply chain with Drupal security team oversight and published vulnerability disclosure process
- **Compliance artefacts on request**Data Processing Agreement, sub-processors list, security annex, and VPAT accessibility documentation

> We built DXPR as a Drupal module, not a SaaS platform, because we believe your content should live where you control it. When your page builder runs inside your own CMS, data residency is not a vendor promise; it is the architecture.
>
>
>
> Jurriaan Roelofs, CEO, DXPR

## Every community deserves a useful website.

A public meeting. A new service. A change in opening hours. The people who rely on your website need clear, current information.

Give local departments approved templates they can update themselves. Let subject experts prepare the content and reviewers check it before it reaches the public, within your Drupal publishing process.

[Try Live Demo →](https://try.dxpr.com)

## Organizations that require domestic data operations.

### Federal and state government

Public affairs, recruitment, and citizen-facing sites that must demonstrate domestic data residency and accessible content delivery.

### Financial services

Investor portals, market education, and IR tooling at exchanges and institutions that need US-resident infrastructure and auditable data flows.

### Healthcare and education

Academic medical centers, university web platforms, and research portals where HIPAA and state privacy laws require domestic data handling.

**Legal, defense or medical infrastructure team with strict AI policies?** [Use your approved private model through an agent and keep visual editing in DXPR Builder.](/drupal-agent-skills#private-models)

## Public oversight. Security campaigns. Pages that cannot wait.

From a Senate communications team to a security platform, see how American organizations give their teams a direct route to publishing with Drupal.

U.S. Senate Sergeant at Arms

### Bring urgent public oversight online.

The Senate Sergeant at Arms (SAA) team used DXPR to launch the Congressional Oversight Commission website on a very short deadline. The same toolkit supports senator websites and the Senate Radio–TV Gallery.

[Read case study](/case-studies/us-senate)

HackerOne

### Give security campaigns room to move.

HackerOne connects organizations with a worldwide community of security researchers. Its Drupal marketing team uses DXPR for visual page building behind product campaigns and security content.

[Read case study](/case-studies/hackerone)

## Compare how page builders handle your data.

SaaS page builders extract your content into vendor-controlled infrastructure. DXPR Builder runs inside your Drupal site. The architecture itself is the compliance guarantee.

| Capability | DXPR Builder | Typical SaaS page builder |
|---|---|---|
| Content stored in your database | ✓ Always | ✕ Vendor cloud |
| US-only infrastructure | ✓ Geolocked | Mixed; may route through non-US regions |
| AI pipelines | ✓ US-hosted endpoints | Varies; routing often undisclosed |
| Vendor lock-in | ✓ None; open-source Drupal module | ✕ Proprietary; content tied to platform |
| Data residency guarantee | ✓ By architecture | By contract only |
| Source code audit | ✓ Open source | ✕ Closed source |
| ADA / Section 508 | ✓ WCAG 2.2 AA with VPAT | Varies; often self-reported |

## Your content, your infrastructure, your jurisdiction.

Talk to us about our Washington, DC infrastructure and your US data residency requirements, or try DXPR Builder in the live demo.

[Talk to Sales](/contact)

[Try Live Demo](https://try.dxpr.com)